cbcvebase.

Debian Ansible vulnerabilities

66 known vulnerabilities affecting debian/ansible.

Total CVEs
66
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH16MEDIUM30LOW15

Vulnerabilities

Page 2 of 4
CVE-2016-3096P3HIGHCVSS 7.8fixed in ansible 2.0.1.0-2 (bookworm)2016
CVE-2016-3096 [HIGH] CVE-2016-3096: ansible - The create_script function in the lxc_container module in Ansible before 1.9.6-1... The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary dire
debian
CVE-2014-2686P3HIGHCVSS 7.5fixed in ansible 1.5.4+dfsg-1 (bookworm)2014
CVE-2014-2686 [HIGH] CVE-2014-2686: ansible - Ansible prior to 1.5.4 mishandles the evaluation of some strings. Ansible prior to 1.5.4 mishandles the evaluation of some strings. Scope: local bookworm: resolved (fixed in 1.5.4+dfsg-1) bullseye: resolved (fixed in 1.5.4+dfsg-1) forky: resolved (fixed in 1.5.4+dfsg-1) sid: resolved (fixed in 1.5.4+dfsg-1) trixie: resolved (fixed in 1.5.4+dfsg-1)
debian
CVE-2016-8614P3MEDIUMCVSS 6.3fixed in ansible 2.2.0.0-1 (bookworm)2016
CVE-2016-8614 [MEDIUM] CVE-2016-8614: ansible - A flaw was found in Ansible before version 2.2.0. The apt_key module does not pr... A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key. Scope: local bookworm: resolved (fixed in 2.2.0.0-1) bullseye: resolved (fixed in 2.2.0.0-1) forky: resolved (fixed in 2.2.0.0
debian
CVE-2018-16837P3HIGHCVSS 7.8fixed in ansible 2.7.1+dfsg-1 (bookworm)2018
CVE-2018-16837 [HIGH] CVE-2018-16837: ansible - Ansible "User" module leaks any data which is passed on as a parameter to ssh-ke... Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list. Scope: local bookworm: resolved (fixed in 2.7.1+dfs
debian
CVE-2013-2233P3HIGHCVSS 7.4fixed in ansible 1.3.4+dfsg-1 (bookworm)2013
CVE-2013-2233 [HIGH] CVE-2013-2233: ansible - Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-... Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys. Scope: local bookworm: resolved (fixed in 1.3.4+dfsg-1) bullseye: resolved (fixed in 1.3.4+dfsg-1) forky: resolved (fixed in 1.3.4+dfsg-1) sid: resolved (fixed in 1.3.4+dfsg-1) trixie: resolved (fixed in 1.3.4+dfsg-1)
debian
CVE-2019-14864P3LOWCVSS 6.5fixed in ansible 2.9.2+dfsg-1 (bookworm)2019
CVE-2019-14864 [MEDIUM] CVE-2019-14864: ansible - Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.... Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data. Scope: local bookworm: resolved (fixed in 2.9.2+dfsg-1) bullseye: resol
debian
CVE-2023-5115P3MEDIUMCVSS 6.3fixed in ansible 5.4.0-1 (bookworm)2023
CVE-2023-5115 [MEDIUM] CVE-2023-5115: ansible - An absolute path traversal attack exists in the Ansible automation platform. Thi... An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path. Scope: local bookworm: resolved (fixed in 5.4.0-1) bullseye: resolved (fixed in 2.10.7+merged+base+2.10.17+dfsg-0+de
debian
CVE-2019-10217P3MEDIUMCVSS 6.5fixed in ansible 2.8.6+dfsg-1 (bookworm)2019
CVE-2019-10217 [MEDIUM] CVE-2019-10217: ansible - A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data s... A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansi
debian
CVE-2021-3583P4HIGHCVSS 7.1fixed in ansible 5.4.0-1 (bookworm)2021
CVE-2021-3583 [HIGH] CVE-2021-3583: ansible - A flaw was found in Ansible, where a user's controller is vulnerable to template... A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special template characters. This flaw allows attackers to perform command injection, which discloses s
debian
CVE-2020-14365P4LOWCVSS 7.1fixed in ansible 2.9.13+dfsg-1 (bookworm)2020
CVE-2020-14365 [HIGH] CVE-2020-14365: ansible - A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 an... A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrar
debian
CVE-2015-6240P4LOWCVSS 7.8fixed in ansible 1.9.2+dfsg-1 (bookworm)2015
CVE-2015-6240 [HIGH] CVE-2015-6240: ansible - The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow loca... The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack. Scope: local bookworm: resolved (fixed in 1.9.2+dfsg-1) bullseye: resolved (fixed in 1.9.2+dfsg-1) forky: resolved (fixed in 1.9.2+dfsg-1) sid: resolved (fixed in 1.9.2+dfsg-1) trixie: resolved (fixed in 1.9.2+dfsg-1)
debian
CVE-2019-10206P4MEDIUMCVSS 6.5fixed in ansible 2.8.6+dfsg-1 (bookworm)2019
CVE-2019-10206 [MEDIUM] CVE-2019-10206: ansible - ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all ... ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. Scope: local bookworm: resolved (fixed in 2.8.6+dfsg-1) bullseye: res
debian
CVE-2024-11079P4MEDIUMCVSS 5.5fixed in ansible 5.4.0-1 (bookworm)2024
CVE-2024-11079 [MEDIUM] CVE-2024-11079: ansible - A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass ... A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks. Scope: local bookworm: resolved (fixed in 5.4.0-1) bullseye: reso
debian
CVE-2018-10855P4LOWCVSS 5.9fixed in ansible 2.5.5+dfsg-1 (bookworm)2018
CVE-2018-10855 [MEDIUM] CVE-2018-10855: ansible - Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task... Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible. Scope: local bookworm: reso
debian
CVE-2024-9902P4MEDIUMCVSS 6.3fixed in ansible 5.4.0-1 (bookworm)2024
CVE-2024-9902 [MEDIUM] CVE-2024-9902: ansible - A flaw was found in Ansible. The ansible-core `user` module can allow an unprivi... A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has traversal permissions on the directory containing t
debian
CVE-2019-10156P4LOWCVSS 5.4fixed in ansible 2.8.3+dfsg-1 (bookworm)2019
CVE-2019-10156 [MEDIUM] CVE-2019-10156: ansible - A flaw was discovered in the way Ansible templating was implemented in versions ... A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed. Scope: local bookworm: resolved (fixed in 2.8.3+dfsg-1) bul
debian
CVE-2018-16876P4MEDIUMCVSS 5.3fixed in ansible 2.7.6+dfsg-1 (bookworm)2018
CVE-2018-16876 [MEDIUM] CVE-2018-16876: ansible - ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information dis... ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data. Scope: local bookworm: resolved (fixed in 2.7.6+dfsg-1) bullseye: resolved (fixed in 2.7.6+dfsg-1) forky: resolved (fixed in 2.7.6+dfsg-1) sid: resolved (fixed in 2.7.6+dfsg-1) trixie: resolved (fixed i
debian
CVE-2019-14905P4LOWCVSS 5.6fixed in ansible 2.9.4+dfsg-1 (bookworm)2019
CVE-2019-14905 [MEDIUM] CVE-2019-14905: ansible - A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x b... A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality o
debian
CVE-2021-20191P4MEDIUMCVSS 5.5fixed in ansible 2.10.7-1 (bookworm)2021
CVE-2021-20191 [MEDIUM] CVE-2021-20191: ansible - A flaw was found in ansible. Credentials, such as secrets, are being disclosed i... A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected. Scop
debian
CVE-2021-20178P4MEDIUMCVSS 5.5fixed in ansible 2.10.7-1 (bookworm)2021
CVE-2021-20178 [MEDIUM] CVE-2021-20178: ansible - A flaw was found in ansible module where credentials are disclosed in the consol... A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality. Scope: local bookworm: resolved (fixed i
debian
Debian Ansible vulnerabilities | cvebase